CVE-2026-18366

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID happens to match the ID of one of the Events Manager WordPress plugin before 7.4.1's own posts.


We have discovered 24,353 live websites that are affected by CVE-2026-18366.

Run a Free Instant Scan




Affected Software

Product  Events Manager for WordPress
Category Wordpress Plugins
Vulnerable Domains24,353 live websites (69% of Events Manager for WordPress install base)
Vulnerable Versions
  • from 7.1 through 7.4.1
Vulnerable Versions Count30 versions ( 28% of all versions)


Common Weakness Enumeration

CWE-269 Improper Privilege Management



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Jakub Herman (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18366
United States6,735 websites



Germany5,876 websites
France1,765 websites
Netherlands1,425 websites
GB1,320 websites
Switzerland779 websites
Italy709 websites
Canada616 websites
Denmark543 websites
Austria389 websites

Website Distribution by TLD

Number of websites using CVE-2026-18366
.com5,359 websites
.de4,745 websites
.org3,791 websites
.nl1,366 websites
.fr972 websites
.ch681 websites
.it542 websites
.co.uk530 websites
.net470 websites
.at413 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18366

Top websites that are affected by CVE-2026-18366. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org United States**,***
*********.*******.org United States**,***
**************.gov United States**,***
********.org United States**,***
*****.br Brazil**,***
****.org France**,***
*****.org United States**,***
****.org United States**,***
**********************.org France**,***
*****************.com United States**,***
See full domain list

FAQ

CVE-2026-18366 is Improper Privilege Management in Events Manager for WordPress
A total of 24,353 websites have been identified as vulnerable to CVE-2026-18366, based on global website indexing conducted by WebTechSurvey.
The Events Manager for WordPress is affected by the CVE-2026-18366 vulnerability.
Events Manager for WordPress versions up to 7.4.1 are vulnerable to CVE-2026-18366.
CVE-2026-18366 is resolved in version 7.4.1 of Events Manager for WordPress.